DPDP Wiki Talk to us

/Glossary · Defined term

Data Processor

Defined in section 2(k) of the Act.

Official definition

Official definition

Verbatim

Act, section 2(k)

(k) “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary;

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data ProcessorData Fiduciary

The Digital Personal Data Protection Act, 2023 defines a "Data Processor" as any person who processes personal data on behalf of a Data Fiduciary. A Data Fiduciary is the person or entity that determines the purpose and means of processing personal data. Under this definition, a Data Processor can be an individual, a company, or any other type of person.\n\nThis definition establishes a specific relationship based on who is in charge of the data. The Data Processor does not decide why the personal data is collected or what the ultimate goal of using it is. Instead, the Data Processor only handles, stores, or otherwise processes the personal data because the Data Fiduciary has asked them to do so.\n\nBy drawing the definition this way, the law creates a clear boundary between the entity that controls the data and the entity that merely performs operations on that data. The key factor that makes a person a Data Processor is that their processing activities are done strictly on behalf of a Data Fiduciary.

Key points

  • A Data Processor is defined as any person who processes personal data. [Section 2(k)]
  • The processing of personal data by a Data Processor must be done on behalf of a Data Fiduciary. [Section 2(k)]

Common misreadings

  • Assuming a Data Processor decides why data is processed; the text specifies they only process data on behalf of a Data Fiduciary.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.